The following types of indicator (IOC) rules are supported. These types may appear in the Category column on the Indicators tab of the Rules page in the Endpoint Security (HX) Web UI.
Type | Description |
|---|---|
User-defined indicator rules that include conditions such as DNS lookups, network connections, and the creation of specific malware files. | |
Imported | Indicator rules imported from SIEM. |
Trellix | Indicator rules imported from other Trellix appliances (such as NX Series or EX series), but not from CM Series. These indicator rules are created from source alerts. See Trellix source alerts . |
FireEye Restricted | Restricted indicator rules imported from DTI. Restricted indicator rules are hidden until one of the conditions in the indicator triggers an alert for an endpoint. |
Trellix-CMS | Indicator rules imported from CM Series. These indicator rules are created from source alerts. See Trellix source alerts . |
Mandiant Intel | Restricted indicator rules imported from DTI. Restricted indicator rules are hidden until one of the conditions in the indicator triggers an alert for an endpoint. |
Mandiant Unrestricted Intel | Unrestricted indicator rules. These indicator rules always appear in the indicator list on the Indicators tab of the Rules page in the Web UI. They are used by Trellix for some internal processing and serve as an indication that the Trellix indicator package is loaded and functional on your appliance. In addition, you can use them as samples when you create custom indicator rules. |
For information about IOC rules, see Managing IOC rules .
Restricted indicator rules
Trellix indicator rules are restricted and stored in the Dynamic Threat Intelligence (DTI) cloud. They are normally hidden from view in the Endpoint Security (HX) Web UI and the API. They are visible only when their existence on an endpoint triggers an alert or when the indicator is provided by another Trellix appliance. Likewise, the conditions associated with Trellix indicator rules can be viewed only when the condition triggers an alert. When all alerts associated with an indicator or condition are removed, the indicator and its associated conditions are hidden again. This streamlines the forensic analysis of alerts because only the pertinent indicator rules and conditions are shown. When visible, Trellix indicator rules can be seen on the Indicators tab of the Rules page in the Web UI.
Unrestricted indicator rules
A few Trellix indicator rules are unrestricted. These indicator rules always appear in the indicator list on the Indicators tab of the Rules page. They are used by Trellix for some internal processing and serve as an indication that the Trellix indicator package is loaded and functional on your appliance. In addition, you can use them as samples when you create custom indicator rules.
The following table briefly describes each unrestricted Trellix indicator of compromise (IOC):
Indicator name | Description |
|---|---|
CRYPMIC RANSOMWARE (FAMILY) | Identifies artifacts associated with the execution of CRYPMIC ransomware family and its variants. |
FIREEYE END2END OSX TEST | Tests that the Trellix indicator package is loaded properly in macOS environments. |
FIREEYE END2END TEST | Tests that the Trellix indicator package is loaded properly in Windows environments. |
JAKU (REPORT) | Identifies an indicator of compromise (IOC) rule derived from information located in the Forcepoint JAKUE report. This includes host-based and network-based indicator rules. |
MALICIOUS SCRIPT CONTENT A (METHODOLOGY) | Looks for potentially malicious scripts run via |
MIMIKATZ (CREDENTIAL STEALER) | Identifies artifacts associated with the execution of MIMIKATZ malware. MIMIKATZ is a freely downloadable binary capable of process injection, Security Account Manager (SAM) hash dumping, and exporting certificates and private keys of the executing user. |
NEUTRINO EXPLOITKIT (EXPLOIT) | Identifies files dropped by the Neutrino exploit kit. An encoded |
POISON IVY (METHODOLOGY) | Identifies artifacts associated with the registry presence of Poison Ivy malware. This indicator uses a registry run key set at |
SUSPICIOUS SCRIPT CREATION (METHODOLOGY) | Identifies the creation and execution of scripts with random names. This technique can drop payloads in phishing emails. |
SUSPICIOUS VBSCRIPT (METHODOLOGY) | Identifies the use of explicit script engine declarations for |
WSCRIPT LAUNCHING POWERSHELL (METHODOLOGY) | Looks for |
Custom indicator rules
You can create custom indicator rules to monitor for evidence of compromise such as the establishment of specific network connections, DNS lookups, and the creation or modification of specific files. Custom alerts occur when a condition in a custom indicator triggers an alert on an endpoint. See Maintaining custom indicator rules .